Explore Problems
Showing 5,712 of 7,559 problems · matching your filters
Credit bureaus fail to notify consumers of dispute investigation outcomes
Consumers who file credit report disputes report never receiving notification of investigation status or results, despite FCRA requirements. Without visibility into the process, they cannot confirm whether inaccurate information was corrected or escalate unresolved cases.
Fraud Dispute Resolution Leaves Cardholders Without Account Access for Days
After unauthorized charges, cardholders can be locked out of online account management and unable to self-issue a replacement card, while dispute hotlines involve hour-plus hold times. The friction compounds the harm of the original fraud and leaves customers without a working card during the investigation.
Card issuers don't disclose when promotional 0% APR periods are ending
Credit card statements display a 0% promotional APR without labeling it as temporary or noting its expiration date, leading cardholders to unknowingly accrue interest once the promotion ends. Issuers decline to refund the resulting interest charges despite the unclear disclosure.
Bank security alert systems fail to fire during active account takeover via phishing
Customers who configure bank security alerts for new device logins and failed password attempts receive no notifications when fraudsters are actively taking over their accounts via phishing. Alert systems that customers rely on as a safety net fail silently at exactly the moment they are needed. The combination of caller ID spoofing and alert failure gives attackers undetected access windows long enough to drain accounts.
Salesforce Locks Essential CRM Features Behind Expensive Add-On Tiers
Salesforce's pricing model places many of its most valuable features in premium add-on tiers, making the true cost of a functional deployment far higher than base plan pricing suggests. This tiered gating disproportionately affects mid-market companies that need advanced capabilities but cannot justify enterprise pricing. The practice has driven sustained interest in CRM alternatives with more transparent feature bundling.
Debt collectors use spoofed numbers and threats to harass debtors and family
A consumer is contacted almost daily by a debt collector using threatening language and spoofed caller-ID numbers that cannot be traced, who also contacts family members by name to pressure repayment of an unverified debt.
Phone Theft Enables Immediate High-Value Zelle and Venmo Fraud Banks Refuse to Refund
Thieves who steal unlocked phones can immediately execute thousands of dollars in Zelle and Venmo transfers before the owner can react. Payment apps treat physical phone possession as sufficient authorization, creating a structural gap where theft of a device equals theft of funds. Banks and payment platforms systematically deny fraud refunds for these transactions because the device was used directly.
Zelle Transfers to Wrong Recipient Cannot Be Recalled by Banks
A single digit error when entering a Zelle recipient phone number sends funds to the wrong person with no recovery path — banks disclaim liability and Zelle has no recall mechanism for voluntary transactions. With hundreds of millions of Zelle transactions per year, the scale of accidental misdirection is enormous. Pre-send recipient identity confirmation and rapid escalation tools for same-day misdirection cases would address a structural gap.
Air-Gapped Networks Have No Passive Threat Detection Without Active Scanning Risk
Security teams protecting air-gapped environments — defense, ICS, nuclear — cannot use conventional network detection tools that require active probes, which risk triggering false alerts or disrupting critical operations. Passive monitoring that can identify C2 beacons and DNS generation algorithm traffic without sending any packets is absent from the market. This leaves some of the highest-value targets with a fundamental detection blind spot.
AI Support Chatbots Hallucinate and Refuse to Escalate to Humans
AI chatbots like Intercom Fin generate responses outside their configured knowledge base and fail to hand off to human agents when users explicitly request it. This erodes customer trust and creates liability for businesses relying on AI-first support. The problem is structural across AI support tools, not limited to any single vendor.
Mortgage servicers cancel approved loan-modification trial plans in error
Homeowners who begin trial loan-modification payments have their plans abruptly canceled due to internal servicer errors, then face unclear reinstatement processes. The confusion delays resolution and increases foreclosure risk.
Credit Bureaus Slow to Block Fraudulent Accounts After Identity Theft
Identity theft victims report difficulty getting credit reporting agencies to block fraudulent accounts within the FCRA-mandated four-day window despite submitting police reports and supporting documentation. This delay leaves victims exposed to continued credit damage from accounts they never opened.
Auto Lenders Report Contradictory Payment-Due and Delinquency Status
Some auto finance companies report a loan simultaneously as having a $0 monthly payment due and as being severely past due, an internally contradictory record that damages the borrower's credit. When borrowers dispute the inaccuracy, the lender can reclassify the dispute as suspected fraud to close the regulatory complaint without addressing the underlying data error.
MCP Servers Inject Context Tokens on Every Message Even When Not Used
Every configured MCP server injects tokens into the context window on each message, regardless of whether that server is needed for the current task. As developers add more MCP servers, context window bloat becomes severe and reduces effective model capacity. No selective MCP loading mechanism exists to activate servers only when relevant.
Cloud AI Coding Agents Require Sharing Codebases; Local Models Lack Performance
Developers using cloud-based AI coding agents like Cursor, Codex, or Claude must expose their codebase to training pipelines. Switching to local models for privacy eliminates the performance needed for real coding tasks. No tool currently solves both privacy and performance simultaneously.
Indian Personal Finance Apps Mandate Bank Linking or SMS Scraping to Build Credit Profiles
Every major personal finance app in India forces users to link bank accounts via Account Aggregator or grant SMS access, then ships data to remote servers for credit profiling and loan marketing. Users who want privacy-respecting expense tracking have no viable alternative.
Bank fails to freeze pending fraudulent wire transfers after timely report
A Citibank customer reported two unauthorized wire transfers totaling $49,000 while they were still pending, but the bank's support process - including repeated call transfers and language barriers - let the transfers clear instead of freezing them.
Bank ACH Dispute Delays Risk Homeowners' Liens and Foreclosure Threats
Consumers who make ACH payments that banks fail to properly process face month-long dispute resolution timelines with no interim protection, even when a missed payment triggers collection agency action and a threatened property lien. The bank's slow, opaque investigation process leaves account holders unable to prove payment was made, risking severe consequences like losing their home.
Banks Advertise Targeted Bonuses Without Disclosing Eligibility Exclusions
Consumers who click personalized, in-dashboard bank promotional offers such as sign-up bonuses are later denied the bonus based on eligibility rules that were never disclosed at the time of the offer. Existing customers get targeted with new-customer style incentives, and internal compliance teams fail to audit their own web portal banners for accurate disclosure, leaving consumers with no recourse besides filing formal complaints.
Malicious VSCode Extensions Can Breach Thousands of GitHub Repositories
A single malicious VSCode extension compromised 3,800 GitHub repositories, exposing a critical gap in extension marketplace security vetting. The extension marketplace provides no meaningful safety signals, leaving developers unable to assess extension trustworthiness at install time.